RodoAssis Profile Banner
Rodolfo Assis Profile
Rodolfo Assis

@RodoAssis

Followers
10K
Following
3K
Media
530
Statuses
3K

That #XSS and #WAF #bypass guy. @BRuteLogic @KN0X55

Brazil šŸ‡§šŸ‡·
Joined March 2018
Don't wanna be here? Send us removal request.
@RodoAssis
Rodolfo Assis
4 years
I don't think that watching/reading #hacking tutorials and collecting BB tips in Twitter or any other social media will make you UNDERSTAND what you are doing and why that happens. Build a solid foundation with PROGRAMMING, NETWORKING, PROTOCOLS and OPERATING SYSTEMS first.
16
65
423
@RodoAssis
Rodolfo Assis
1 day
Copy+Paste issue!. When pasting it be aware that "l .search" here became " http://l .search".
0
0
1
@grok
Grok
3 days
Join millions who have switched to Grok.
160
305
2K
@RodoAssis
Rodolfo Assis
1 day
I'm just 1 click away from knowing if there's a WAF (and which one) with my super simple "WAFme" bookmarklet. JavaScript:w='?j=<script>&';l=location;q=w;if(q=replace('?',w);location=' https://'+l.hostname+l.pathname+q+l.hash. #XSS
1
4
44
@RodoAssis
Rodolfo Assis
2 days
That JavaScript scenario is full of tricks.
@KN0X55
KNOXSS
2 days
#XSS tricks to #Bypass #WAF in the URL Context.by @BRuteLogic. => HTMLi + Double Encoding + Embedded Bytes. JavaScript:"<Svg/OnLoad=alert%25%0A26lpar;1)>". JavaScript:"\%0A74Svg/On%0ALoad=alert%25%0A26lpar;1%25%0A26rpar;>". Lab KNOXSS has similar ones! šŸ˜‰
Tweet media one
0
0
6
@RodoAssis
Rodolfo Assis
4 days
That's why I say I'm an artist, not a hacker:. I depend on inspiration to work.
0
1
4
@RodoAssis
Rodolfo Assis
7 days
RT @RodoAssis: Hey bug hunter! . Do you have a WAF or any other filter in your way?. Let's COLLABORATE! 🤩. Any bug, 50/50 just DM me with d….
0
1
0
@RodoAssis
Rodolfo Assis
8 days
Hey bug hunter! . Do you have a WAF or any other filter in your way?. Let's COLLABORATE! 🤩. Any bug, 50/50 just DM me with details. #hack2learn
0
1
12
@RodoAssis
Rodolfo Assis
9 days
Another day, another way to bypass a WAF. Stay tuned, I'm documenting them all!.
1
1
13
@RodoAssis
Rodolfo Assis
15 days
RT @KN0X55: We just published our 1st blog post! . We hope to be just the beginning of everything #XSS related we know. Check it out! šŸ˜‰ā€¦.
Tweet card summary image
knoxss.pro
Finding XSS vulnerable targets is not an easy task when doing Bug Bounties but these thoughts will help you.
0
4
0
@RodoAssis
Rodolfo Assis
17 days
Change the world (for the better) or die trying?.
1
0
3
@RodoAssis
Rodolfo Assis
18 days
If you blindly trust LLMs like chatGPT, Claude or Gemini you are smart as they are. Check my chat with Claude starting with "XSS Filter Bypass" but ending up on how absolutely useless it is for anything serious. Claude is considered to be "very smart".
0
2
6
@RodoAssis
Rodolfo Assis
22 days
Tweet media one
0
0
6
@RodoAssis
Rodolfo Assis
1 month
It's super hard to take care of 50+ cats and dogs every single day, you have no idea.
0
0
4
@RodoAssis
Rodolfo Assis
1 month
What's wrong here? . Try to PoC a XSS using ALert(1) instead of alert(1)!. Bypassing a filter with incorrect syntax is not a bypass.
@RodoAssis
Rodolfo Assis
1 month
Just found that in a serious, academic whitepaper. 🤦
Tweet media one
1
0
9
@RodoAssis
Rodolfo Assis
1 month
Just found that in a serious, academic whitepaper. 🤦
Tweet media one
0
0
2
@RodoAssis
Rodolfo Assis
1 month
Imperva guys fix their WAF so badly that you just need to change the order of the attributes in the previous bypass and it works. 🤪
Tweet media one
0
1
17
@RodoAssis
Rodolfo Assis
2 months
Tweet media one
0
0
4
@RodoAssis
Rodolfo Assis
2 months
Why this is important?. Unless you test every entry point w/ something like alert(1) exactly that way, no quotes, nothing, you won't be able to spot eval() like scenarios w/ a regular #XSS vector like <Img/Src/OnError=alert(1)>. Unless you read all the JS source code, of course.
@BRuteLogic
Brute Logic
2 months
A DOM-Based #XSS Polyglot. 1;/*'"><Img/Src/OnError=/**/confirm(1)//>. If your input happens to end up in the DOM via innerHTML or eval(), it works for both cases. PoCs below. innerHTML: eval():
0
1
4
@RodoAssis
Rodolfo Assis
2 months
RT @RodoAssis: Between white and black, there's a lot of grey. #Hacking . That's something you learn in LIFE itself. #hack2learn https://t.….
0
2
0
@RodoAssis
Rodolfo Assis
2 months
Between white and black, there's a lot of grey. #Hacking . That's something you learn in LIFE itself. #hack2learn
Tweet media one
0
2
10